codereview-config

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The codereview-config skill is coherently aligned with its stated purpose of validating safe defaults, secret handling, and environment parity. It emphasizes best practices (no hardcoded secrets, startup validation, environment-specific configurations, secret rotation, and documentation for feature flags) and avoids actionable execution flows that would enable external data exfiltration or supply-chain compromise. There are no evident unintended data flows, credential forwarding to unknown binaries, or autonomous real-world actions. Overall, the footprint is benign and proportionate to the described purpose with low security risk; the few minor anomaly signals pertain to typical best-practice guidance rather than active threat vectors.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 10:48 AM
Package URL
pkg:socket/skills-sh/xinbenlv%2Fcodereview-skills%2Fcodereview-config%2F@688830856c6dff326e9f0d04016ea79774eecfd2